Viewing profile — ericselin
ericselin
HN member- Joined
- Mon, Nov 15, 2021, 11:09 AM UTC
- HN karma
- 131
- Public activity
- 28 items
- HN profile
- View on Hacker News ↗
About ericselin
No profile information was provided.
Recent public activity
-
comment
Comment #46616951
FreeSwewing is an awesome project by Joost De Cock! You should totally check it out if you're into sewing. And if you're into digital sovereignty tou should totally check out stati…
- story
-
comment
Comment #45544783
Based on what I've seen, there's no way to get that project into the PSL. I would recommend you to have the content available at projectcontent.com if the main site is project.com,…
-
comment
Comment #45544561
The thing is, for users, having a separate domain wouldn't have made any difference without the PSL. And you cannot get on there before you're big enough - which I'd say is roughly…
-
comment
Comment #45544514
Sure, and sorry for being so unclear. The point of my post was meant to be a) Google has this enormous cannon, is this "right"? And b) they will use it to kill anything bigger than…
-
comment
Comment #45544463
Ok, I see. You mean the possibility of users impersonating statichost.eu itself. That is actually a good point, and the exact reason why user subdomains are required to have a dash…
-
comment
Comment #45544385
Author here. What kind of security negligence are you referring to? What would be a specific attack vector that I left open? Regarding the PSL - and I can't believe I'm writing thi…
-
comment
Comment #45543772
Thank you for this hacker-minded and sharp comment! And for what it's worth, it feels great to actually pay for something Google provides!
-
comment
Comment #45543658
Many commenters are implying that there is a security issue here, and that I'm putting everyone in danger. That is quite frankly a pretty absurd claim to just casually make. I'm of…
-
comment
Comment #45542960
Author here. I understand that my post and what I'm trying to say is unclear. And that there are too many different aspects to all this. What I'm trying to say in the post specific…
-
comment
Comment #45542121
So the problem here is that Alice on alice.statichost.page might set a cookie for the `.statichost.page` domain if she's careless (which is sometimes the case with Alice). This coo…
-
comment
Comment #45540753
https://github.com/publicsuffix/list/wiki/Guidelines#validat... "Projects that are smaller in scale or are temporary or seasonal in nature will likely be declined. Examples of this…
-
comment
Comment #45540230
Please note that this tool (PSL) is not available until you have a significant user base. Which probably means a significant amount of spam as well.
-
comment
Comment #45540178
Fair enough! :)
-
comment
Comment #45540096
Since there's a lot of discussion about the Public Suffix list, let me point out that it's not just a webform where you can add any domain. There's a whole approval process where o…
-
comment
Comment #45539680
The thing is, you cannot just add any domain to the PSL. You need a significant amount of users before they will include your domain. Before recently, there really was no point in …
-
comment
Comment #45539454
I respectfully disagree with your premise. In this specific case, yes, "Google does good thing" in a sense. That is not why I'm saying Google has too much power. "Too much" is rela…
-
comment
Comment #45539351
You are right, it would still affect all users. Until the pending PSL inclusion is complete, that is. But it now separates my own resources, such as the website and dashboard of st…
-
comment
Comment #45539250
(Author here) This is all true. The main assumption from my part is that anything remotely important or even sensitive should be and is hosted on a domain that is _not_ companysubd…
-
comment
Comment #45539188
That is a great point. When I see these sites I'm always seeing a dozen red flags, and maybe the biggest one is that it's showing a "NatWest" banking site or something and is hoste…
-
comment
Comment #45539144
You are right, of course. I'm not sure if those of you who disagree with me think that Safe Browsing did its job (which it did!), that Safe Browsing is a good thing (which it maybe…
-
comment
Comment #45539070
I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this cas…
-
comment
Comment #45538981
This is of course true! It just takes an incident like this to get ones head out of ones ass and actually do it. :)
-
comment
Comment #45538874
Good question, it probably shouldn't be legal. Enforcing the law on these behemoths is another problem, though... :)
- story